CVE-2026-44511 Details
Description
Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated. This vulnerability is fixed in 4.20.0 and 5.6.0.
A vulnerability exists in Katalyst Koi versions prior to 4.20.0 and between 5.0.0 and 5.6.0, where admin session cookies were not invalidated upon logout. This allowed an attacker with access to a valid admin session cookie to continue accessing admin features until the cookie expired or session secrets were rotated. The issue affects applications using Koi admin authentication, where an admin session cookie may have been exposed, cached, intercepted, or otherwise retained after logout.
Users are advised to upgrade to Katalyst Koi versions 4.20.0 or 5.6.0. Instructions for applying the update can be found in the Katalyst Koi GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/katalyst/koi/security/advisories/GHSA-4cx3-3c38-j9vv | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Katalyst Koi | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |
Volerion